Mobile Device Secondary Authentication Enrollment and Token Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current computer-based authentication systems face challenges in enhancing security without significantly disrupting user experience, particularly in requiring users to manually input complex security information for secondary factor authentication.
Innovation Solution
A system that enrolls a mobile device as a secondary factor authentication device, generating a key code for enrollment, and automatically performs secondary factor authentication by establishing a connection between the primary and secondary devices, reducing user intervention through proximity-based authentication tokens and device identifiers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual input of complex security information is required for secondary factor authentication, then security is enhanced, but user disturbance and operation complexity increase
Solution Approach 1:
The mobile device automatically performs secondary factor authentication without requiring manual user input. The device uses its own resources (processor, communication interface, stored credentials) to generate and transmit authentication tokens, enabling self-service authentication that maintains security while eliminating user disturbance.
Solution Approach 2:
The patent replaces manual mechanical input (typing, keyboard entry) with automated electronic communication. The mobile device electronically transmits authentication tokens to the authentication server, substituting the mechanical act of manual input with automated digital communication to reduce user disturbance.
2Ease of operation
If automated secondary factor authentication is implemented, then user disturbance is reduced, but device complexity and system integration requirements increase
Solution Approach 1:
The mobile device leverages its existing universal capabilities (processor, communication interface, storage) to perform authentication functions. Rather than adding dedicated hardware, the system uses the device's general-purpose components to handle authentication, reducing overall system complexity while achieving automation.
Solution Approach 2:
The authentication server acts as an intermediary between the mobile device and the resource access system. This intermediary handles the complex authentication logic and communication protocols, simplifying the integration requirements for the mobile device and the resource access system while enabling automated authentication.
3Speed
If proximity-based authentication tokens are used, then authentication speed is improved, but security vulnerability to proximity attacks increases
Solution Approach 1:
The mobile device pre-stores authentication tokens and credentials in its memory before the authentication event. When authentication is required, the device quickly retrieves and transmits the pre-stored tokens, enabling fast authentication without requiring real-time computation or generating vulnerability windows for proximity attacks.
Solution Approach 2:
The system uses periodic authentication tokens that are valid for limited time windows. The mobile device transmits tokens at specific intervals during the authentication process, creating a rhythmic authentication pattern that maintains speed while limiting the window for proximity-based attacks.
Data Source
AI summary
A computer-implemented method comprising: receiving, from a primary factor authentication device by one or more computer systems, a request to enroll a mobile device as a secondary factor authentication device; andenrolling by the one or more computer systems the mobile device as a first, secondary factor authentication device.


